First published: Thu Nov 11 2021(Updated: )
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212788.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | <=3.0 - 3.0.0.4 | |
Ibm Security Key Lifecycle Manager | <=3.0.1 - 3.0.1.5 | |
Ibm Security Key Lifecycle Manager | <=4.0 - 4.0.0.3 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.0 - 4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.1 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.0 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.1 | |
Ibm Security Key Lifecycle Manager | >=3.0<=3.0.0.4 | |
Ibm Security Key Lifecycle Manager | >=3.0.1<=3.0.1.5 | |
Ibm Security Key Lifecycle Manager | >=4.0<=4.0.0.3 | |
Ibm Security Key Lifecycle Manager | =4.1.0 | |
Ibm Security Key Lifecycle Manager | =4.1.0.1 | |
Ibm Security Key Lifecycle Manager | =4.1.1 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38981 is medium with a score of 5.3.
The affected software for CVE-2021-38981 includes IBM Tivoli Key Lifecycle Manager versions 3.0 - 3.0.0.4, 3.0.1 - 3.0.1.5, 4.0 - 4.0.0.3, and 4.1.0 - 4.1.0.1, as well as IBM Security Guardium Key Lifecycle Manager versions 4.1.0 and 4.1.1.
A remote attacker can obtain sensitive information when a detailed technical error message is returned in the browser, which could be used in further attacks against the system.
The IBM X-Force ID for CVE-2021-38981 is 212788.
You can find more information about CVE-2021-38981 on the IBM X-Force Exchange website and the IBM Support page.